Use-After-Free Vulnerability in Envoy Proxy by Envoy Project
CVE-2026-47207

6.5MEDIUM

Key Information:

Vendor

Envoyproxy

Status
Vendor
CVE Published:
26 June 2026

What is CVE-2026-47207?

Envoy Proxy, an open-source edge and service proxy for cloud-native applications, is vulnerable to a use-after-free error caused by improperly crafted gRPC messages sent from an ext_proc server. Specifically, if the first response in a batch results in the destruction of the gRPC stream object, Envoy may fail when processing subsequent ProcessingResponse messages. This issue affects specific versions of Envoy Proxy, and remediation steps have been provided in the latest security updates.

Affected Version(s)

envoy >= 1.38.0, < 1.38.3 < 1.38.0, 1.38.3

envoy >= 1.37.0, < 1.37.5 < 1.37.0, 1.37.5

envoy >= 1.36.0, < 1.36.9 < 1.36.0, 1.36.9

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.